Third-party Risk Management

  • Release version: Xanadu
  • Updated July 31, 2025
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Third-party Risk Management

    The ServiceNow® GRC: Third-party Risk Management (TPRM) application helps organizations proactively identify, assess, and mitigate risks associated with their third-party relationships. It centralizes the management of third-party portfolios, risk assessment, scoring, and remediation to protect organizational interests and ensure compliance.

    Show full answer Show less

    Key Features

    • Risk Assessment and Monitoring: Identify and continuously monitor potential risks linked to third parties, using questionnaires and due diligence processes.
    • Due Diligence Requests: Request and manage third-party risk due diligence to evaluate engagement risk levels.
    • Approval Workflows: Configure approval levels and rules to approve or reject due diligence requests based on assessment results.
    • Contract Risk Management: Incorporate specific contractual provisions to mitigate identified risks during contract negotiations.
    • User Interfaces: Utilize both the Smart Assessment Engine and the legacy Vendor Risk Management (VRM) classic UI to perform risk tasks.
    • Digital Resilience Registers: Maintain registers of ICT third-party service provider contracts within the Vendor Management Workspace.
    • Risk Intelligence Integration: Manage, request, and integrate risk intelligence reports and scores from external providers to gain insights into third-party trustworthiness.
    • Third-party Portal: Facilitate communication by enabling third-party contacts to respond to questionnaires, provide documentation, and address tasks and issues.

    Implementation and Integration

    • Activate or upgrade TPRM by downloading it from the ServiceNow Store and configuring it to meet organizational needs.
    • Extend TPRM capabilities by integrating with other ServiceNow applications and external risk intelligence providers.
    • Transition from the Classic Assessment Engine to the Smart Assessment Engine to leverage enhanced features and updated setup requirements.

    Support and Resources

    • Access detailed reference materials covering tables, properties, forms, and roles within the TPRM application.
    • Engage with the GRC community for questions and peer support.
    • Utilize the Known Error Portal for troubleshooting known issues.
    • Explore developer resources for app building and contact Customer Service for additional assistance.

    The ServiceNow® GRC: Third-party Risk Management (TPRM) application enables you to proactively identify, assess, and mitigate risks that are associated with your third-party relationships. TPRM provides a centralized process for managing your portfolio of third parties, assessing and scoring risk, and performing remediation.

    Get started

    Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release note information for all released apps, see the ServiceNow Store version history release notes.

    Troubleshoot and get help