---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Work in the VRM classic UI

# Working in the VRM Classic user interface {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 Minuten Lesedauer

While you can continue to use the legacy user interface to perform Vendor Risk Management tasks, the Vendor Management Workspace offers enhanced TPRM features and more useful reports.

[Configure a risk assessment to recur on a schedule](https://servicenow-prod.fluidtopics.net/Kq06rcn5KzneAbO~kNPAWg "Configure a third-party risk assessment to recur on a schedule to regularly update risk results for a third party or an engagement.")

:   Configure a third-party risk assessment to recur on a schedule to regularly update risk results for a third party or an engagement.

    Role required: sn_vdr_risk_asmt.vendor_assessor

[Create a VRM third party record](https://servicenow-prod.fluidtopics.net/xqxBm7bxnNp4HcJvv~m70g "Set up the key data and contact information for a third party that your organization will engage.")

:   Configure a third-party risk assessment to recur on a schedule to regularly update risk results for a third party or an engagement.

    Role required: admin or sn_vdr_risk_asmt.vendor_risk_manager.

[Setting up VRM third-party hierarchies and engagements](https://servicenow-prod.fluidtopics.net/cvT8LNhmtoCSxtFTr2Y9lg "Create third-party hierarchies by defining the parent-child relationships between the parent third party and all of their subsidiaries. You do this task because some organizations work with third parties that have subsidiaries (or subsidiaries of subsidiaries) that can pose a potential risk to your business. You can perform assessments at each subsidiary organization and roll up the results to calculate an overall risk score for the parent third party.")

:   Create third-party hierarchies by defining the parent-child relationships between the parent third party and all of their subsidiaries. You do this task because some organizations work with third parties that have subsidiaries (or subsidiaries of subsidiaries) that can pose a potential risk to your business. You can perform assessments at each subsidiary organization and roll up the results to calculate an overall risk score for the parent third party.

    Role required: sn_vdr_risk_asmt.vendor_risk_manager or sn_vdr_risk_asmt.vendor_assessor.

[Define a VRM engagement](https://servicenow-prod.fluidtopics.net/pk_a_E9SrdJm6vubYp_WWA "Define an engagement so that you can assess the risks that are associated with the services or products offered by a third party. Engagements can also represent the products or services that are provided to the parent third party, either directly or from departments, partners, or subsidiaries that you can also assess for risk.")
:
    Define an engagement so that you can assess the risks that are associated with the services or products offered by a third party. Engagements can also represent the products or services that are provided to the parent third party, either directly or from departments, partners, or subsidiaries that you can also assess for risk.  
    Tipp:  
    Any person with access to your instance at your organization can request an engagement. That process is typically more streamlined and more effective than the process described here, where a Third-party risk (TPR) manager or TPR assessor defines an engagement. For more information, see [Request due diligence for a third-party engagement](https://servicenow-prod.fluidtopics.net/LLHkVhAy~3pTurSZLZ67rQ "Request due diligence to assess the risk that is associated with doing business with an engagement. By conducting due diligence, you gain access to the most up-to-date, comprehensive, and accurate information before making a decision on entering into a business relationship.").

    Role required: sn_vdr_risk_asmt.vendor_risk_manager or sn_vdr_risk_asmt.vendor_assessor.

[VRM third-party risk tiering assessments](https://servicenow-prod.fluidtopics.net/NGBCuvkjWrvnqHLBr0nDtA "Organizations use risk tiering to classify their third parties into categories of potential risk posed at the time of onboarding. The standard predefined risk tiers are None, Low, Minor, Moderate, High, and Critical. Each risk tier has associated assessment questions and document requests.")
:   Organizations use risk tiering to classify their third parties into categories of potential risk posed at the time of onboarding. The standard predefined risk tiers are None, Low, Minor, Moderate, High, and Critical. Each risk tier has associated assessment questions and document requests.

[Managing external risk assessments --- Legacy process](https://servicenow-prod.fluidtopics.net/FZqhtGg67HWCunTqIykT4g "Before the TPR manager closes an assessment, stakeholders create issues and tasks, usually during the Generating observations state. The TPR assessor assigns third parties as needed and communicates using comment streams to achieve closure on non-compliance. The third-party primary contact uses the Third-party portal to view all assessments.")
:   Before the TPR manager closes an assessment, stakeholders create issues and tasks, usually during the Generating observations state. The TPR assessor assigns third parties as needed and
    communicates using comment streams to achieve closure on non-compliance. The third-party primary contact uses the Third-party portal to view all assessments.

[Create an external assessment --- Legacy process](https://servicenow-prod.fluidtopics.net/GMwSORNNgiTSAcJwcw36ZQ "Create an assessment and initiate the third-party risk assessment life cycle. An external assessment specifies the details for the third party or engagement and defines the plan for completing the assessment.")
: Create an assessment and initiate the third-party risk assessment life cycle.  
Wichtig:  
Starting with version 18.1.3 of Third-party Risk Management the Vendor Risk Overview dashboard is deprecated. If Third-party Risk Management was installed prior to 18.1.3 the Vendor Risk overview dashboard is still available for your use.

