aaο ABDULLAH AL OWASI
← Back to portfolio

P03 / Third-party risk / Independent work sample

Third-party risk.

A vendor decision needs more than a completed questionnaire.

The decision
behind the work.

Select proportionate vendor due diligence from service, data, access, AI, location, criticality, and dependency context.

Methodology and scope are defined in the project manifest. Listed capabilities describe the module design; source files show the implemented subset.

Assessment approach

  1. Inherent-risk tiering
  2. Adaptive evidence request
  3. Fourth-party concentration
  4. AI supplier due diligence
  5. Residual-risk decision
  6. Continuous change monitoring

Evidence
to request.

Start with source records, owner confirmation, scope and observation dates. A completed template alone does not establish operating effectiveness.

Defined output contract

  • vendor-scope.json
  • evidence-request.json
  • risk-decision.json
  • monitoring-obligations.json

The manifest defines these expected artifacts; confirm their existence and completion in source before relying on an output.

Read the full manifest ↗

Review & decision boundaries

Remediation sequence

Record each finding with its evidence reference, risk rationale, accountable owner, target date and closure test. Escalate missing evidence rather than treating it as a pass.

Present management with the supported conclusion, remaining uncertainty and a specific decision request.