Procurement Workflows

Open-source workflows owned by or involving Procurement. Review the steps, responsibilities and evidence, then download templates for your AssureSwarm instance.

All workflows 212 IT 92 HR 11 Finance 27 Internal Audit 45 Risk Management 32 Compliance & Legal 32 Privacy 11 Procurement 15 Executive 20 AI Governance 11 Facilities 7 Business Operations 9
  • Network & Provider Service Monitoring — IT; with Procurement · 5 steps
    Operate the monthly cycle that keeps network devices hardened and controlled and network-service documentation (security features, service levels, management responsibilities, including outsourced services) current, monitoring delivered services for conformance and addressing deviations. Review external providers' activity, service status, and security-relevant events against contractual obligations through their logs and reports, confirm cross-organizational audit-exchange methods and identity-context preservation, and feed every deviation into a single owned remediation log.
  • Outsourced & Critical-Component Development Oversight — Procurement; with IT · 6 steps
    Each quarter, review every active outsourced and third-party development engagement for secure-development, IP-ownership, and audit-rights contract terms, verify deliverables against requirements with security-testing evidence on file, and screen developers of critical systems before granting development-environment access. Maintain the register of components critical to security or mission and the rationale and assurance evidence behind every specialized or custom development decision made because commercial items could not meet requirements.
  • Quarterly Third-Party AI Evaluation Cycle — AI Governance; with Procurement · 7 steps
    Operate the quarterly cycle in which the AI product team commissions an independent third-party evaluator to test every in-scope AI system for adversarial robustness and jailbreak resistance, harmful and out-of-scope outputs, agent-specific high-risk outputs, hallucination rates, and unsafe or unauthorized tool calls. The test scope, categories, and pass thresholds are fixed in advance, then every finding is triaged against those pre-agreed thresholds by category and severity. Failed categories are driven through remediation and evaluator retest, and the evaluator report is formally accepted or returned for rework. The cycle closes by publishing the accepted evaluation evidence — trust-portal summary, customer-facing attestation, and evidence register — and tuning the guardrails from what the evaluation found.
  • Subservice Organization & Third-Party Personnel Oversight — Procurement; with HR · 7 steps
    On the annual per-vendor cycle with quarterly issue follow-up, the vendor risk manager enriches each subservice organization's Vendor register entry, verifies its contracts and assurance reports bind it to the security, data-processing, and third-party personnel-security commitments matching its mapped control objectives, and maps the assurance report's complementary user-entity controls (CUECs) to the organization's internal Controls. Every identified gap becomes a tracked Issue followed to closure, and the cycle closes into an archived, auditor-ready vendor file.
  • Supplier Service Registry & Critical Supplier Assessment — Procurement · 8 steps
    The vendor risk manager maintains the register of supplier-delivered services - the systems and data each service touches and its internal relationship owner - keeping it current as services onboard, change, or exit, and runs security and risk assessments of critical suppliers before acquisition or engagement, recording results and triggering reassessment when services, dependencies, or risk profiles change.
  • Supply-Chain Integrity & OPSEC Operations — IT; with Procurement · 5 steps
    Operate the standing supply-chain integrity program: inspect each period's critical system and component receipts for tamper-evidence and authenticity, keep provenance and chain-of-custody records current, and disposition suspected counterfeits with inspector-training refresh where lapses appear. In the same monthly cycle, review the register of sensitive supply-chain information to confirm disclosure remains limited to parties with a validated need to know and remediate any overexposure found.
  • System and Third-Party Risk Review — Risk Management; with IT, Procurement · 2 steps
    Evaluate system criticality, data flows, supplier evidence, gaps and compensating controls before accepting its risk posture.
  • Third-Party ICT Vendor Regulatory Assurance — Procurement; with Compliance & Legal · 5 steps
    Assess third-party and ICT vendor regulatory obligations, gaps, remediation, and register updates for DORA, FFIEC, and related regimes.
  • Third-Party Risk Program & Vendor Oversight Cycle — Procurement; with Executive · 6 steps
    Each quarter, the Vendor Risk Program Lead refreshes the third-party risk program's governing artifacts - the SCRM plan and policy, the criticality-ranked vendor inventory, the DORA Article 28(3) contract register, concentration-risk view, and critical-provider exit-strategy status - then executes this cycle's tiered reassessments, drives recorded vendor risks to remediation, and confirms external/cloud provider oversight and supplier incident-notification coverage remain current.
  • Third-Party Vendor Assurance Engagement — Internal Audit; with Procurement · 8 steps
    Run an IA-led third-party assurance engagement covering governance, risk tiering, control environment, monitoring, exclusions, and reporting.
  • Third-Party Vendor Risk Lifecycle — Procurement · 9 steps
    Operate the enterprise vendor risk lifecycle from inventory and questionnaire through SOC review, C-SCRM controls, contract gates, monitoring, and reassessment.
  • Vendor Due Diligence & Contracting Gate — Procurement; with Privacy · 9 steps
    For each new vendor engagement or contract renewal, this pre-contract gate runs on the vendor's register entry (the Vendor item — created for a net-new vendor, enriched for a renewal): tier the vendor by criticality, run proportionate due diligence across security posture, financial and operational risk, and supply-chain exposure, and document the acceptance decision before binding the contract to required security, privacy, and applicable regulatory clauses. It has no upstream workflow — the engagement trigger is its own entry point. Named deliverables: the vendor due-diligence report, the documented risk-acceptance decision, the executed contract bound to its security/privacy/regulatory clauses, and — where personal data is involved — the signed written privacy commitments obtained before access begins. On close it enrolls the Vendor in ongoing monitoring and hands the archived gate record to the third-party risk monitoring / vendor oversight lifecycle.
  • Vendor Offboarding & Secure Termination — Procurement; with IT · 8 steps
    Execute a vendor's contractual exit provisions end to end on each relationship termination: revoke all access and credentials, transition the service to its successor, return or verifiably destroy organizational data, securely dispose of dedicated components and tooling using defined techniques, and retain the required post-relationship evidence.
  • Vendor Risk Assessment and Disposition — Procurement; with Risk Management, IT · 2 steps
    Assess the actual supplier's contracts, assurance reports, access, continuity and exit evidence; obtain expert challenge and an authorized reliance disposition.
  • Vendor SOC 1/SOC 2 Report Review & CUEC Mapping — Procurement; with IT · 5 steps
    Review vendor SOC reports, exceptions, CUECs, bridge letters, and reliance conclusions for controls assurance and service-organization dependencies.
Privacy Terms