---
sourceDocument: Yokohama Release Notes
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/release-notes

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Release Notes

ft:clusterId :

    - rn

bundleId :

    - rn


---

# Third-party Risk Management release notes

# Third-party Risk Management release notes {#ariaid-title1}

Release version: Yokohama  
Updated January 30, 2025  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 8 minutes to read  
The ServiceNow®
Third-party Risk Management (TPRM) application provides a centralized process for managing your portfolio of third parties and their engagements, assessing and scoring risk, and performing remediation. TPRM was enhanced and updated in the Yokohama release.

## About Third-party Risk Management {#grc-tprm-rn__grc-tprm-rn-highlights}

* Pre-populate questionnaires for entities and engagements that are associated with the same active third party by using responses from complete questionnaires.
* Respond to questionnaires by using a Microsoft Excel questionnaire template.
* Explore and analyze assessment data at various levels by using the Third-party insights dashboard and the TPRM custom analytics dashboard.
* Stay aligned with stricter regulatory compliance and emerging third-party risk governance by using the new Standardized Information Gathering (SIG) questionnaire content available for 2025.
{#grc-tprm-rn__ul_kpy_5dv_gdc}

See [Third-party Risk Management](https://www.servicenow.com/docs/access?context=third-party-risk-mgt-landing-page&version=yokohama&pubname=yokohama-governance-risk-compliance&ft:locale=en-US) for more information.{#grc-tprm-rn__grc-tprm-rn-highlights-2}

## Activation and other requirements

Important:  
Third-party Risk Management is available in ServiceNow Store. For details, see the "Activation information" section of these release notes.

Activation information

:   Install Third-party Risk Management by requesting it from ServiceNow Store. Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#grc-tprm-rn__grc-tprm-rn-activation-1}

Upgrade information

:   Starting with the Vancouver release, if you're a VRM user upgrading to TPRM, from an earlier release, you must run each upgrade sequentially to ensure that fix scripts run correctly. This means upgrading from one release to the next rather than skipping to the
    latest release. Not running scripts in the correct order can result in data inconsistencies, broken functionalities, and conflicts.{#grc-tprm-rn__grc-tprm-rn-upgrade-info-1}

    For more information on upgrading from VRM to TPRM, see [Third-party Risk Management upgrade information](https://servicenow-prod.fluidtopics.net/QkXtISKEKdcNwKl8Nld5Dg#grc-tprm-upgrade-info "ServiceNow Third-party Risk Management application upgrade information for the Yokohama release.").{#grc-tprm-rn__grc-tprm-rn-upgrade-info-2}

    For existing TPRM customers, after upgrading to version 20.2.4, data from the Industry column in the Company \[core_company\] table is automatically migrated to the tprm_industry column. Migration can take
    several hours depending on the number of records in the Company \[core_company\] table. After migration, a system log message confirms that the migration is complete. Review the Company \[core_company\] table content and update any
    customizations referencing the Industry field to use tprm_industry. After verifying the migration and updating customizations, you can drop the Industry column.{#grc-tprm-rn__grc-tprm-rn-upgrade-info-3}

## Third-party Risk Management upgrade information {#ariaid-title2}

ServiceNow®
Third-party Risk Management application upgrade information for the Yokohama release.

### Important information for upgrading Vendor Risk Management to Yokohama {#grc-tprm-upgrade-info__section_cqv_gbn_k2c}

Starting with the Vancouver release, if you're a VRM user upgrading to TPRM, from an earlier release, you must run each upgrade sequentially to ensure that fix scripts run correctly. This means upgrading from one release to the next rather than skipping
to the latest release. Not running scripts in the correct order can result in data inconsistencies, broken functionalities, and conflicts.

### Plugin requirements {#grc-tprm-upgrade-info__section_j3v_hcn_k2c}

TPRM

* Activate the Third-party Risk Management application \[com.sn_vdr_risk_asmt\].
* Activate the Third-party Risk Due Diligence application \[com.sn_tprm_dd\].
* Activate the Vendor Risk Management Workspace application \[sn_vrm_ws\] if you want to use the Vendor Risk Management workspace.
{#grc-tprm-upgrade-info__ul_fs5_3cn_k2c}  
VRM

* Activate the Vendor Risk Management application \[com.sn_vdr_risk_asmt\].
* Activate the Vendor Risk Management Workspace application \[sn_vrm_ws\] if you want to use the Vendor Risk Management workspace.
{#grc-tprm-upgrade-info__ul_tmg_mcn_k2c}

For more information on licensing or metering, see [Tracking a managed activity](https://www.servicenow.com/docs/access?context=tprm-managed-activity&version=yokohama&pubname=yokohama-governance-risk-compliance&ft:locale=en-US), [Third-party Risk Management (TPRM) Licensing](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1431058) and [Vendor Risk Management (VRM) Licensing](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1362674).

### VRM to TPRM changes {#grc-tprm-upgrade-info__section_lkp_3bn_k2c}

* The name of the application changed from Vendor Risk Management to Third-party Risk Management as part of the Vancouver release.
* The internal assessment \[sn_vdr_asmt_internal_assessment\] table is introduced, extending the tiering assessment \[sn_vdr_risk_asmt_vdr_tiering_assessment\] table.
* The Due Diligence Review (DDR) workflow is introduced, which uses both the internal assessment and the external (VRA) assessment.  
  Note:  
  If you have customizations on the Tiering assessment \[sn_vdr_risk_asmt_vdr_tiering_assessment\] and VRA \[sn_vdr_risk_asmt_assessment\] tables, they might need modifications to work with the DDR workflow.
* The Third-party Scores \[sn_vdr_risk_asmt_security_score\] table has been relabeled to Risk Intelligence Scores \[sn_vdr_risk_asmt_security_score\] to reduce confusion.
* All instances of "vendor" are changed to "third party" in the user interface, though some global instances might remain unchanged.  
  Note:  
  If you don't want to use the due diligence workflow, your original workflow (Tiering assessment and External assessments (VRAs) should be the same).
{#grc-tprm-upgrade-info__ul_ovg_mbn_k2c}

### VRM and TPRM data model {#grc-tprm-upgrade-info__section_dnp_sbn_k2c}

The Vendor Risk Management data model primarily uses the term "vendor" and includes the Tiering assessment \[sn_vdr_risk_asmt_vdr_tiering_assessment\] and VRA \[sn_vdr_risk_asmt_assessment\] tables.

The Third-party Risk Management data model uses the term "third-party" in most user interface elements and introduces the DDR workflow, which uses both internal \[sn_vdr_asmt_internal_assessment\] and
\[sn_vdr_risk_asmt_assessment\] external assessments.

The following models show VRM's and TPRM's capabilities.  
Figure 1. VRM data model

The components included in the Vendor Risk Management data model are as follows:  
* Tiering assessment \[sn_vdr_risk_asmt_vdr_tiering_assessment\]
* Company \[core_company\]
* Vendor risk assessment \[sn_vdr_risk_asmt_assessment\]
* Vendor engagement \[sn_vdr_risk_asmt_vendor_engagement\]
* Vendor contact \[vm_dr_contact\]
* Assessment metric type \[asmt_metric_type\]
* Assessment template \[sn_vdr_risk_asmt_assessment_template\]
* Engagement risk scoring rule \[sn_vdr_risk_asmt_engagement_risk_scoring_rule\]
* Engagement level risk rating \[sn_vdr_risk_asmt_engagement_level_rating\]
{#grc-tprm-upgrade-info__ul_c4l_23n_k2c}  
Figure 2. TPRM data model

The components included in the Third-party Risk Management data model are as follows:  
* Risk intelligence score \[sn_vdr_risk_asmt_security _score\]
* Internal assessment \[sn_vdr_asmt_internal_assessment\]
* Tiering assessment \[sn_vdr_risk_asmt_vdr_tiering_assessment\]
* Event-driven management history \[sn_tprm_dd_rule_execution_history\]
* Third-party due diligence request \[sn_tprm_dd_request\]
* Company \[core_company\]
* Event-driven management rule \[sn_tprm_dd_generation_rule\]
* Third-party risk assessment \[sn_vdr_risk_asmt_assessment\]
* Third-party engagement \[sn_vdr_risk_asmt_vendor_engagement\]
* Vendor contact \[vm_dr_contact\]
* Assessment metric type \[asmt_metric_type\]
* Assessment template \[sn_vdr_risk_asmt_assessment_template\]
* Third-party risk issue \[sn_vdr_risk_asmt_issue\]
* Engagement risk scoring rule \[sn_vdr_risk_asmt_engagement_risk_scoring_rule\]
* Engagement level risk rating \[sn_vdr_risk_asmt_engagement_level_rating\]
{#grc-tprm-upgrade-info__ul_v5z_f4n_bcc}

## May 2025 {#ariaid-title3}

The ServiceNow®
Third-party Risk Management (TPRM) application provides a centralized process for managing your portfolio of third parties and their engagements, assessing and scoring risk, and performing remediation. TPRM was enhanced and updated in the Yokohama release.

### What's new {#grc-tprm-rn-2025-05__grc-tprm-rn-new-features}

[New Standardized Information Gathering (SIG) questionnaire content](https://www.servicenow.com/docs/access?context=grc-sig-integration&version=yokohama&pubname=yokohama-governance-risk-compliance&ft:locale=en-US)
:   Use the updated SIG templates for 2025 after upgrading to version 20.1.x as part of the Third-party Risk Management application. The latest SIG questionnaires help your organization stay aligned with stricter regulatory compliance and emerging third-party risk governance, covering a wide range of
    security and privacy concerns.
{#grc-tprm-rn-2025-05__grc-tprm-rn-new-features-1}

### What's changed {#grc-tprm-rn-2025-05__grc-tprm-rn-changed-features}

[Multiple legal entities making use of the services for contracts](https://www.servicenow.com/docs/access?context=tprm-drtp-reg-contract&version=yokohama&pubname=yokohama-governance-risk-compliance&ft:locale=en-US)
:   If you have the third-party assessor role \[sn_vdr_risk_asmt.vendor_assessor\], add multiple legal entities that are using services as part of a contract record in the digital resilience third-party registers within the Vendor Management Workspace. Including all entities that are using services associated with a contract is essential for maintaining transparency, helping ensure compliance, and enhancing operational resilience.
{#grc-tprm-rn-2025-05__grc-tprm-rn-changed-features-1}

## Yokohama General Availability {#ariaid-title4}

The ServiceNow®
Third-party Risk Management (TPRM) application provides a centralized process for managing your portfolio of third parties and their engagements, assessing and scoring risk, and performing remediation. TPRM was enhanced and updated in the Yokohama release.

### What's changed {#grc-tprm-rn-2025-03__grc-tprm-rn-changed-features}

[Codes and additional identification information for ICT third-party service providers](https://www.servicenow.com/docs/access?context=tprm-create-ICT-thirdparty-serv-prov-form&version=yokohama&pubname=yokohama-governance-risk-compliance&ft:locale=en-US)
:   If you have the third-party assessor role \[sn_vdr_risk_asmt.vendor_assessor\], help ensure compliance with DORA regulations by adding additional code types and a legal name to third-party and third-party engagement records in the digital resilience third-party registers within
    the Vendor Management Workspace. Include this information when the legal name of a third party differs from its commonly recognized name, or when you need to record multiple identification codes like a EUID, LEI, or
    Country code. When supply chain, assessment, or contract records are associated with a third party or third-party engagement using the EUID code type, all relevant fields will be automatically populated.

[Function types for ICT third-party service providers](https://www.servicenow.com/docs/access?context=tprm-create-new-function-form&version=yokohama&pubname=yokohama-governance-risk-compliance&ft:locale=en-US)
:   If you have the third-party assessor role \[sn_vdr_risk_asmt.vendor_assessor\], help ensure compliance with DORA regulations by using Business capability as an additional function type for function records in the digital resilience third-party registers within the Vendor Management Workspace.
{#grc-tprm-rn-2025-03__grc-tprm-rn-changed-features-1}

## Yokohama {#ariaid-title5}

The ServiceNow®
Third-party Risk Management (TPRM) application provides a centralized process for managing your portfolio of third parties and their engagements, assessing and scoring risk, and performing remediation. TPRM was enhanced and updated in the Yokohama release.

### What's new {#grc-tprm-rn-release__grc-tprm-rn-new-features}

[TPRM personalized dashboards](https://www.servicenow.com/docs/access?context=tprm-monitor-dashboards&version=yokohama&pubname=yokohama-governance-risk-compliance&ft:locale=en-US)
:   Improve your decision-making process by exploring and analyzing your assessment data at various levels by using the Third-party insights dashboard and the TPRM custom analytics dashboard. If you have the Third-party risk manager \[sn_vdr_risk_asmt.vendor_risk_manager\] or Third-party risk assessor \[sn_vdr_risk_asmt.vendor_assessor\] role, you
    can create and share your own dashboards and reports. If you're a third-party risk manager, you can also customize the report layouts, widgets, and data views to prioritize key metrics and workflows that align with your
    individual roles and risk programs.

[Quick start tests for TPRM](https://www.servicenow.com/docs/access?context=quick-start-tests-grc-vrm&version=yokohama&pubname=yokohama-governance-risk-compliance&ft:locale=en-US)
:   Verify that TPRM works as expected after upgrades and deployments of new applications or integrations by running quick start tests. If you customized TPRM, copy the quick start tests and configure them for your customizations.
{#grc-tprm-rn-release__grc-tprm-rn-new-features-1}

### What's changed {#grc-tprm-rn-release__grc-tprm-rn-ui-changes}

[TPRM personalized dashboards](https://www.servicenow.com/docs/access?context=tprm-monitor-dashboards&version=yokohama&pubname=yokohama-governance-risk-compliance&ft:locale=en-US)
:   The Third-party insights dashboard and the TPRM custom analytics dashboard are now available from the Dashboards page of the Vendor Management Workspace.

[Third-party portal import modal](https://www.servicenow.com/docs/access?context=tprm-excel-template-support&version=yokohama&pubname=yokohama-governance-risk-compliance&ft:locale=en-US)
:   The import modal now enables you to respond to questionnaires by using a Microsoft Excel template. You can download the questionnaire, complete it according to the included instructions, and import the final version into the Third-party portal.
{#grc-tprm-rn-release__grc-tprm-rn-ui-changes-1}

[Pre-populate responses using questionnaires](https://www.servicenow.com/docs/access?context=tprm-assessing-tpr&version=yokohama&pubname=yokohama-governance-risk-compliance&ft:locale=en-US)
:   If you have the Third-party risk assessor \[sn_vdr_risk_asmt.vendor_assessor\] or Third-party risk manager \[sn_vdr_risk_asmt.vendor_risk_manager\] role, you can enable third-party and engagement contacts to review and update
    responses only if necessary by pre-populating questionnaires for engagements and entities with responses from completed questionnaires that are associated with the same third party. The attachment, duration, and signature type
    responses are excluded. This feature also helps ensure data consistency and accuracy.

[Microsoft Excel questionnaire template](https://www.servicenow.com/docs/access?context=tprm-excel-template-support&version=yokohama&pubname=yokohama-governance-risk-compliance&ft:locale=en-US)
:   Streamline the due diligence process by enabling third-party and engagement contacts to respond to questionnaires using a Microsoft Excel template by downloading the questionnaire as a template, completing it according to the included instructions, and importing the final version into the Third-party portal. This feature update
    enhances flexibility by enabling third-party and engagement contacts to provide information outside the third-party portal. Third-party risk assessors \[sn_vdr_risk_asmt.vendor_assessor\] and Third-party risk managers
    \[sn_vdr_risk_asmt.vendor_risk_manager\] can access this feature and respond to questionnaires on behalf of Third-party and engagement contacts through the Vendor Management Workspace.
{#grc-tprm-rn-release__grc-tprm-rn-changed-features-1}

