---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Configure

# Configuring Third-party Risk Management {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Configuring Third-party Risk Management

ServiceNow's Third-party Risk Management (TPRM) application helps you manage and assess risks associated with third-party vendors.
You can activate or upgrade TPRM by downloading the necessary applications from the ServiceNow Store and configuring them to fit your organizational requirements.
The configuration process involves a series of setup tasks that enable secure access, role assignments, communication, and data integration with existing systems.
Show full answer Show less  

## Key Setup Tasks

* **Activate Core Applications:** Install the Third-party Risk Management app, Due Diligence Request workflow, and Vendor Risk Management Workspace to enable core TPRM functionalities. Admin role is required.
* **Security Configuration:** Add authentication policies and post-authentication context to ensure secure access for external third parties.
* **Role and Group Assignments:** Assign TPRM roles to users and organize users into groups based on responsibilities to streamline task management and notifications.
* **Property and Feature Configuration:** Set TPRM properties tailored to your operations and optionally enable features like the Risk Concentration Map, which requires a Google license.
* **Email Setup:** Enable email communications with third-party contacts for notifications about assessments and issues. Customize email header and footer images to align with your branding.
* **Data Import:** Optionally import existing third-party, assessment, and issue data from other platforms such as Aravo or ProcessUnity without additional charges.
* **Third-party Contact Management:** Configure external users' access and permissions on the Third-party portal, enabling them to interact securely and perform assessment-related tasks.
* **Language Activation:** Optionally configure TPRM to use languages other than the default American English.
* **Testing and Validation:** Run quick-start tests to verify that TPRM functions correctly after upgrades or customizations, adjusting tests to your instance data.
* **Workspace Customization:** Optionally configure related lists in the Vendor Management Workspace for improved navigation and record management.

## Practical Benefits for ServiceNow Customers

Following the checklist ensures a structured and efficient deployment or upgrade of the TPRM application, enabling secure vendor risk assessments and streamlined communication with third-party contacts. Proper role and group management enhances process control and task visibility. Optional features like the Risk Concentration Map provide visual risk insights, while importing existing data facilitates smooth transitions from other platforms. Email and portal configurations increase engagement and responsiveness with third parties.

By completing these configurations, customers can expect a robust, secure, and user-friendly environment to manage third-party risks effectively, improving overall risk governance and compliance.  
You can activate or upgrade TPRM, by downloading the applications from the ServiceNow Store and then configuring the settings to meet your needs.

## Configuration overview {#tprm-configuring__section_rnj_vln_syb}

By performing the tasks in the Setup tasks for TPRM checklist, you can upgrade or install the TPRM application. After you've completed the tasks, you can perform additional configuration as described in [Classic assessment configuration](https://servicenow-prod.fluidtopics.net/gam5c858LRrJSbsFn6__1A "The TPR manager and TPR admin roles involve a broad variety of responsibilities. After the TPRM base system is set up, you configure additional settings that enable and enhance everyday risk-assessment tasks.").  
Note:  
For any custom messages you create, it is your responsibility to generate the corresponding `sys_ui_message` records. This step is crucial if you want the custom messages to be extracted and translated.

## Initial setup and upgrade checklist for TPRM {#tprm-configuring__section_f23_5rj_wxb}

{#tprm-configuring__table_ytv_tf2_kxb__entry__2}

| Task | Description |
|-|-|
| Activate the Third-party Risk Management app \[com.sn_vdr_risk_asmt\]. | To see the instructions for downloading a GRC application from the ServiceNow® Store, see [Download a GRC application from the ServiceNow Store for the first time](https://servicenow-prod.fluidtopics.net/eYj0wRntYiS7rr7a0SPNyA "Downloading an application from the ServiceNow Store for the first time involves several easy steps. Some steps are performed on the ServiceNow Store and some in your ServiceNow AI Platform instance."). Important: The base system includes many sample questions that you can use in your question bank. To include sample questionnaires, select Load demo data while installing the app. Role required: admin |
| Activate the Due diligence request workflow application \[com.sn_tprm_dd\]. | To see the instructions for downloading a GRC application from the ServiceNow® Store, see [Download a GRC application from the ServiceNow Store for the first time](https://servicenow-prod.fluidtopics.net/eYj0wRntYiS7rr7a0SPNyA "Downloading an application from the ServiceNow Store for the first time involves several easy steps. Some steps are performed on the ServiceNow Store and some in your ServiceNow AI Platform instance."). Role required: admin |
| Activate the Vendor Risk Management Workspace application \[sn_vrm_ws\]. | To see the instructions for downloading a GRC application from the ServiceNow® Store, see [Download a GRC application from the ServiceNow Store for the first time](https://servicenow-prod.fluidtopics.net/eYj0wRntYiS7rr7a0SPNyA "Downloading an application from the ServiceNow Store for the first time involves several easy steps. Some steps are performed on the ServiceNow Store and some in your ServiceNow AI Platform instance."). Role required: admin |
| Add an authentication policy to enable secure access for external third parties. | For more information, see [Add an authentication policy to enable secure access for external third parties](https://www.servicenow.com/docs/access?context=add-policy-to-context&version=australia&pubname=australia-platform-security&ft:locale=en-US). Role required: admin Use the platform post-authentication policies to enable third parties to secure access to your instance. For background information on this feature, see [Post-authentication context](https://www.servicenow.com/docs/access?context=post-auth-context&version=australia&pubname=australia-platform-security&ft:locale=en-US). |
| Assign TPRM roles to users and user groups. | Assign roles to users before you implement or use the Third-party Risk Management application. Assigning roles in a well-organized manner simplifies and improves process management and helps to ensure that users are promptly notified of tasks in their areas of responsibility. For more information, see [Assign TPRM roles to users and user groups](https://servicenow-prod.fluidtopics.net/KcehcGq2QbX9Y8SAQk4jnQ "Assign roles to users before you implement or use the Third-party Risk Management application. Assigning roles in a well-organized manner simplifies and improves process management and helps to ensure that users are promptly notified of tasks in their areas of responsibility."). Role required: admin |
| Add users to groups based on their responsibilities. | Assign users to groups before you implement or use the Third-party Risk Management application. Each group contains users with particular roles. Well-organized user groups simplify and improve process management and help to ensure that users are promptly notified of tasks in their areas of responsibility. For more information, see [Add users to groups based on responsibilities](https://servicenow-prod.fluidtopics.net/uEjnxiP~mKUNvCbtz3G_MA "Assign users to groups before you implement or use the Third-party Risk Management application. Each group contains users with particular roles. Well-organized user groups simplify and improve process management and help to ensure that users are promptly notified of tasks in their areas of responsibility."). Role required: admin |
| Configure TPRM properties. | Configure property settings for a variety of TPRM operations. For more information, see [Configure TPRM properties](https://servicenow-prod.fluidtopics.net/9lJM8SW1APiGqRwL7gM6Zg "Configure property settings for a variety of TPRM operations."). Role required: admin |
| Enable the TPRM Risk concentration map. | This task is optional. For more information, see [Enable the TPRM Risk concentration map](https://servicenow-prod.fluidtopics.net/8dKp~cABB86VqBH8Jhs2ew "After you install the Risk concentration map feature, you must install a Google license to enable the feature."). Role required: admin After you install the Risk concentration map feature, you must install a Google license to enable the feature. |
| Enable your emails with third-party contacts. | Configure email communication with third-party contacts to enable email notification of assessments and issues. For more information, see [Enable email with third-party contacts](https://servicenow-prod.fluidtopics.net/CdTAIBRRnELUGj_DsudhyQ "Configure email communication with third-party contacts to enable email notification of assessments and issues."). Role required: admin |
| Update header and footer images for email notifications. | Update the header and footer images used in email notifications by modifying image records. For more information, see [Update the header and footer for email notifications](https://servicenow-prod.fluidtopics.net/Z7XzrdAGvUq7lD7tCXKqAA "Update the header and footer images used in email notifications by modifying image records for Third-party Risk Management."). Role required: admin |
| Import the existing data from other systems. | This task is optional. Import existing data (third parties, engagements, assessments, questionnaires, issues, and so on) from other systems (like the Aravo platform, the ProcessUnity platform, and so on). You aren't charged for importing the data. For more information, see [Import existing data from other systems](https://servicenow-prod.fluidtopics.net/83nxJpm0qMastuGlv4J6fQ "Import existing data (third parties, engagements, assessments, questionnaires, issues, and so on) from other systems (like the Aravo platform, the ProcessUnity platform, and so on). You aren’t charged for importing the data."). Role required: admin |
| Set up third-party contacts. | Third-party contacts are external users at the third-party organization. They use the Third-party portal to securely organize, prioritize, and perform tasks like responding to questionnaires for assessments, performing tasks, and communicating with your risk-assessment staff regarding issues. You grant access to the Third-party portal and specify the permissions for third-party contacts. For more information, see [Set up third-party contacts](https://servicenow-prod.fluidtopics.net/kIZpvjl~kPc6YAxrR6CXoA "Set up your third-party contacts so that you can send assessments, address issues, and communicate any additional required information with these contacts using Third-party Risk Management."). Role required: admin or sn_vdr_risk_asmt.vendor_risk_manager |
| Activate a language. | This task is optional. The ServiceNow AI Platform uses American English by default. You can configure TPRM to use a different language. For more information, see [Activate a language](https://www.servicenow.com/docs/access?context=t_ActivateALanguage&version=australia&pubname=australia-platform-administration&ft:locale=en-US). Role required: admin |
| Run the quick-start tests for third-party risk management. | This task is optional. Verify that TPRM still works after you make configuration changes such as applying an upgrade or developing an application. Copy and customize the quick-start tests to pass when using your instance-specific data. For more information, see [Run the Quick Start tests for Third-party Risk Management](https://servicenow-prod.fluidtopics.net/FTkTsJAB89rHIFvdzf9CYQ "Verify that TPRM still works after you make configuration changes such as applying an upgrade or developing an application. Copy and customize the quick-start tests to pass when using your instance-specific data."). |
| Configure related lists in the Vendor Management Workspace. | This task is optional. Configure the related lists that appear in the vertical navigation layout on record pages in the Vendor Management Workspace. For more information, see [Configure related lists for vertical navigation on record pages](https://servicenow-prod.fluidtopics.net/1IJDvLNTZ3dtH4e7ZZXh_g "Configure the related lists that appear in the vertical navigation layout on record pages in the Vendor Management Workspace."). |
[Table 1. Setup tasks for TPRM]

{#tprm-configuring__table_ytv_tf2_kxb}
**Related concepts**   

* [Classic assessment configuration](https://servicenow-prod.fluidtopics.net/gam5c858LRrJSbsFn6__1A "The TPR manager and TPR admin roles involve a broad variety of responsibilities. After the TPRM base system is set up, you configure additional settings that enable and enhance everyday risk-assessment tasks.")
* [Smart assessment configuration](https://servicenow-prod.fluidtopics.net/Iw1VKDeXTdPK4OYFAkof2A "The TPR manager and TPR admin roles involve a broad variety of responsibilities. After the TPRM base system is set up, you configure Smart Assessment Engine specific settings as well as other assessment settings that enable and enhance everyday risk-assessment tasks. TPRM admins can enable SAE and work with SAE templates.")
* [Configure AI capabilities in Third-party Risk Management](https://servicenow-prod.fluidtopics.net/9qRfU95imIKpOFHN1zHRzg "If you have the admin role, you can configure the ServiceNow Otto for Third-party Risk Management (TPRM) application so that agents can use the generative AI capabilities in Vendor Management Workspace and Core UI.")

