---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# TPRM with Policy and Compliance Management

# Integrating Third-party Risk Management with GRC: Policy and Compliance Management {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 Minuten Lesedauer

The GRC: Policy and Compliance Management integration updates the compliance status of controls and control objectives based on the questionnaire responses from a third party or engagement. Third-party risk (TPR) managers with the
Compliance Manager \[sn_compliance.manager\] role can associate controls with specific questions, third parties, and engagements.

If you have the Policy and Compliance Management application installed, TPR managers with the Compliance Manager role can perform several key tasks that help manage and assess Third-party compliance.  
* You can associate third parties and engagements to specific control objectives. This association creates controls for the third party or engagement, establishing a direct connection between them and the compliance management process.For more information, see [Manually add a control to a third party or engagement](https://servicenow-prod.fluidtopics.net/8~v2nURttoVsmZllU8uqiA "If you’re using both Policy and Compliance Management and Third-party Risk Management, you can associate controls with third parties and engagements. Controls can be marked as compliant or non-compliant.").

* You can individually link the question to multiple control objectives for each question in a questionnaire template. This enables for a granular and detailed assessment of compliance.For more information, see [Manually add a control objective to a question](https://servicenow-prod.fluidtopics.net/IWRHgXPOhK6cLpTVX4dYag "If you’re using both Policy and Compliance Management and Third-party Risk Management, you can associate control objectives and controls with questions. Controls can be marked as compliant or non-compliant based on the response to the question.").

* When third parties and engagements respond to questionnaires, the system automatically updates the compliance status of the linked controls. If they provide an incorrect answer, the associated controls are marked as non-compliant. Conversely, correct answers keep the controls compliant.
{#pc-assessment-integration__ul_o4d_42c_x2c}  
Hinweis:  
Although it is not possible to directly map control objectives to questions in SAE questionnaires, SAE provides the capability to flag controls as compliant or non-compliant through post-assessment actions.

All third parties are automatically categorized into an entity type called Vendors. This helps ensure that each third party and engagement is represented as an entity.

When an entity, such as a third party or engagement, is associated with a control objective a corresponding control is created for that entity. This association links the third party or engagement with the control, which can
influence the compliance status of the control.

In the context of Third-party Risk Management, each question in a questionnaire template can be individually linked to multiple control objectives through a related list. When a questionnaire is sent to a third party and the third
party responds with an incorrect answer, the controls associated with the linked control objectives are marked as non-compliant. Conversely, if the third party provides the correct answer, the controls remain compliant.

This feature helps ensure that the compliance status of controls is dynamically updated based on the third party or engagements responses, providing a real-time and accurate assessment of their compliance. Both Policy and Compliance Management users and Third-party risk assessors \[sn_vdr_risk_asmt.vendor_assessor\] can monitor the status of a control.

For more information on implementing Policy and Compliance Management, see [Implementing Policy and Compliance Management](https://servicenow-prod.fluidtopics.net/8pPLkTACWWw7Yf5vRrkOfA "Use the steps in the GRC: Policy and Compliance Management application checklist to download the Policy and Compliance Management from the ServiceNow Store, and get it ready for operation. Mandatory and optional setup steps, as well as an implementation checklist are provided to simplify the setup.").
* **[Manually add a control to a third party or engagement](https://servicenow-prod.fluidtopics.net/8~v2nURttoVsmZllU8uqiA)**   
  If you're using both Policy and Compliance Management and Third-party Risk Management, you can associate controls with third parties and engagements. Controls can be marked as compliant or non-compliant.
* **[Manually add a control objective to a question](https://servicenow-prod.fluidtopics.net/IWRHgXPOhK6cLpTVX4dYag)**   
  If you're using both Policy and Compliance Management and Third-party Risk Management, you can associate control objectives and controls with questions. Controls can be marked as compliant or non-compliant based on the response to the question.

**Zugehörige Konzepte**   

* [Assessing your third-party risk](https://servicenow-prod.fluidtopics.net/bEwWgwU4cnCVGB54_IrVcg "Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.")
* [Implementing Policy and Compliance Management](https://servicenow-prod.fluidtopics.net/8pPLkTACWWw7Yf5vRrkOfA "Use the steps in the GRC: Policy and Compliance Management application checklist to download the Policy and Compliance Management from the ServiceNow Store, and get it ready for operation. Mandatory and optional setup steps, as well as an implementation checklist are provided to simplify the setup.")  
**Zugehörige Tasks**   

* [Manually add a control to a third party or engagement](https://servicenow-prod.fluidtopics.net/8~v2nURttoVsmZllU8uqiA "If you’re using both Policy and Compliance Management and Third-party Risk Management, you can associate controls with third parties and engagements. Controls can be marked as compliant or non-compliant.")
* [Manually add a control objective to a question](https://servicenow-prod.fluidtopics.net/IWRHgXPOhK6cLpTVX4dYag "If you’re using both Policy and Compliance Management and Third-party Risk Management, you can associate control objectives and controls with questions. Controls can be marked as compliant or non-compliant based on the response to the question.")

