Vendor Security Review process diagram
This is a worked example. Wavelength built the diagram below from the description on this page. Nobody drew it by hand.
What was said
Procurement submits a vendor request when a new supplier is needed. Security sends the vendor a security questionnaire. The security team rates the vendor's risk. If the risk is high, legal reviews the data processing agreement. If the risk is low, the vendor goes straight to approval. Legal approves or flags redlines in the DPA. Once approved, the vendor is added to the approved vendor register.
The diagram
What is in this flow
- Systems: None.
- People and teams: Procurement, Security, Legal.
- Decisions: High Risk?, DPA Redlines?.
- Size: 13 steps and 14 connections.
Steps
- Procurement
- Vendor Request (Procurement)
- Security
- Send Questionnaire (Security)
- Rate Risk (Security)
- High Risk?
- Legal
- Review DPA (Legal)
- DPA Redlines?
- Resolve Redlines (Legal)
- Approve Vendor (Security)
- Add to Register (Procurement)
- Vendor Onboarded
Mermaid code
Copy this into any Markdown file, GitHub README, or Mermaid Live to render the same flow.
flowchart TD
n1(Procurement)
n2([Vendor Request])
n3(Security)
n4[Send Questionnaire]
n5[Rate Risk]
n6{High Risk?}
n7(Legal)
n8[Review DPA]
n9{DPA Redlines?}
n10[Resolve Redlines]
n11[Approve Vendor]
n12[Add to Register]
n13([Vendor Onboarded])
n1 -->|submits| n2
n2 -->|routes to| n3
n3 -->|sends| n4
n4 -->|vendor returns| n5
n5 -->|rates| n6
n6 -->|Yes| n7
n6 -->|No| n11
n7 -->|reviews| n8
n8 -->|checks| n9
n9 -->|Yes| n10
n9 -->|No| n11
n10 -->|revised| n8
n11 -->|approved| n12
n12 -->|adds to register| n13
Map your own process
Describe your version out loud, or paste the transcript of a call. Wavelength draws the flow as you talk, and you can edit it by voice, by prompt, or by hand.
Every new account starts with 7 days of Pro. No card needed.
This example is part of our guide for compliance and audit.