---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# DMS system

# Document Management system in Third-party Risk Management {#ariaid-title1}

* Release version: Australia
* 
* Updated May 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Document Management system in Third-party Risk Management

The Document Management System (DMS) in Third-party Risk Management (TPRM), introduced in version 21.1.x, provides a centralized repository for storing and managing third-party documents throughout the vendor lifecycle.
It enhances third-party collaboration and internal workflows by streamlining evidence tracking, reducing document duplication, and improving audit readiness through document reuse across assessments, contracts, issues, and tasks.
Show full answer Show less  
Users can access DMS via the Vendor Management Workspace for internal users or the Third-party portal for external users. Role-based permissions control access, with TPR assessors, managers, and administrators having write access, and assessment reviewers having read-only access. The system supports metadata, version control, search, reporting, and comprehensive audit tracking for all document actions.

## Key Features

* Third-party contacts can upload and manage documents through the third-party portal, while internal users manage document records via the Vendor Management Workspace.
* Supports document versioning, metadata management, download options, and audit tracking for all actions and version history.
* Documents can be linked to multiple TPRM records such as Tasks, Issues, Engagements, and Assessments with automatic roll-up for traceability and reporting.
* Role-based permissions allow primary contacts and internal users to manage document sharing and access controls effectively.
* Powerful search and reporting capabilities enable filtering by document type, risk category, expiration, and third-party association, supporting inventory, linkage, and audit reports.
* Integration with Smart Assessment Engine (SAE) enables documents and metadata to be accessible during assessment activities, reducing manual effort and improving assessment accuracy.
* AI-driven capabilities via Now Assist and ServiceNow Otto for TPRM offer automation skills like issue summarization, smart document Q\&A, and information extraction to expedite document-heavy workflows.

## Document Life Cycle and Traceability

Each document captures essential metadata such as creation date, type, description, version, and status to support classification, workflows, and reporting. Multiple versions are supported with version history accessible to authorized roles. Documents linked to TPRM records maintain formal relationships called references, which facilitate lifecycle tracking and prevent duplicate links. All document actions, including uploads and version updates, are fully audit logged and accessible to authorized users for transparency.

## Collaboration and Insights

The system tracks all document-related activities, including approvals and rejections, in audit logs to ensure transparency. Users can leverage advanced search and reporting to monitor document usage, status, and relationships, supporting compliance and operational oversight.

## Limitations

* External users cannot preview documents and must download them to view content.
* The third-party association field is optional unless the document is linked to a third party, in which case it is required.
* Document creation and versioning are currently handled in separate steps.

## Practical Value for ServiceNow Customers

ServiceNow customers using TPRM can expect improved document collaboration and lifecycle management with centralized control and auditability. The integration with assessment workflows and AI-powered automation accelerates risk management processes, reduces manual effort, and enhances compliance readiness. Role-based access and reporting capabilities ensure secure and transparent document handling across internal teams and third-party contacts.  
Learn how the enhanced Document Management system supports third-party collaboration and internal workflows in Third-party Risk Management (TPRM).

## Document Management Overview {#tprm-dms__overview}

Starting with version 21.1.x, the Document Management System (DMS) in Third-party Risk Management (TPRM) provides a centralized repository for storing, organizing, and managing third-party documents throughout the vendor life cycle. DMS streamlines evidence tracking, reduces duplication, and
improves audit readiness by enabling document reuse across assessments, contracts, issues, and tasks. Access DMS in the Vendor Management Workspace or third-party portal to create, manage, and reference documents. Primary contacts manage permissions in the portal. TPR assessors \[sn_vdr_risk_asmt.vendor_assessor\], TPR managers
\[sn_vdr_risk_asmt.vendor_risk_manager\], and TPR administrators have write access, while third-party assessment reviewers \[sn_vdr_risk_asmt.vendor_assessment_reviewer\] have read-only access. DMS supports metadata, version control,
search, reporting, and audit tracking for all document actions.  
The DMS is accessible for internal users through the Documents module in the Vendor Management Workspace as shown in the following example.Figure 1. Document Management System in Vendor Management Workspace  
The DMS is accessible for external users through the Third-party portal as shown in the following example.Figure 2. Document Management System in the Third-party portal

## Key capabilities {#tprm-dms__capabilities}

* Third-party contacts can upload and manage documents using the third-party portal. For more information, see [Upload and manage documents in the third-party portal](https://servicenow-prod.fluidtopics.net/sU1CNRIGMzK4AncCt_sObQ "Use the third-party portal to upload and manage documents for assessments, engagements, issues, and tasks in Third-Party Risk Management (TPRM).").

* Internal users can create and access document records through the Documents module in the Vendor Management Workspace.

  For more information, see [Create a document record](https://servicenow-prod.fluidtopics.net/KFx3LLH5k7pvxAbxt48Rtw "Use the Document Management system to create document records in Third-party Risk Management.").
* Users can manage document versions, download attachments, and track their metadata.For more information, see [Create a document version](https://servicenow-prod.fluidtopics.net/U~QYqXtGXH9x2BjDAb9DCg "Use the document management system to version documents in Third-Party Risk Management (TPRM).").

* Documents can be linked to multiple TPRM record types with auto-rollup:
  * Tasks
  * Issues
  * Engagements
  * Assessments

  For more information, see [Link documents to a TPRM record](https://servicenow-prod.fluidtopics.net/HAf2M6ScYEt8I3VktAWcjA "Use the Document Management system to link documents to assessments, engagements, issues, and tasks for traceability in Third-party Risk Management (TPRM).").
* Internal users can manage role-based permissions for primary contacts and other internal users. For more information, see [Define document sharing permissions](https://servicenow-prod.fluidtopics.net/_mJFJWANXCIrJG_JyXw2bA "Controls who can view, edit, or manage a document using the Document Management system in Third-party Risk Management (TPRM).").

* Each document version supports download options, advanced search and reporting for metadata and relationships, and complete audit tracking of actions and version history.

## Document life cycle and traceability {#tprm-dms__document-lifecycle-and-traceability}

Each document captures metadata including creation date, type, description, version, and status. Metadata is used for classification, reporting, and workflow routing.

Each document supports multiple versions. TPR assessors, managers, and administrators can upload new versions, view version history, and download attachments for any version. Versions are sorted by creation date in descending order.  
Documents can be linked to assessments, engagements, issues, and tasks. These references automatically roll up to related third-party records. Duplicate references aren't allowed.  
Note:  
A linked document is a document record associated with another record (assessment, engagement, issue, or task) for traceability and reporting. Linking creates a formal relationship that supports life-cycle tracking. A reference is the entry that represents this link, shown in the document's References tab and the related record's Documents list. Each reference includes metadata like record type and ID. The key difference is that linking is the action and a reference is the result. Multiple references to one document are possible, but duplicate references to the same record aren't allowed.

All document actions including uploads and version updates are tracked for audit purposes. Audit logs are accessible to authorized users.

## Collaboration and insights {#tprm-dms__section_oqr_tvp_3hc}

All actions, including approvals and rejections, are tracked in the audit log for transparency and reporting. You can search documents by metadata fields and generate reports on document usage, status, and relationships. Filters
include document type, risk category, expiration date, and third-party association. You can generate reports on document usage, version history, and linked records using the Reports module or Performance Analytics.  
Report types can include:

* Document inventory report with metadata and version details.
* Linkage report showing documents associated with assessments, engagements, and tasks.
* Audit report for document actions and life-cycle events.
{#tprm-dms__ul_evr_yz4_3hc}

## DMS and Smart assessment {#tprm-dms__section_gx2_zzs_13c}

If you have the third‑party risk manager role \[sn_vdr_risk_asmt.vendor_risk_manager\], you can access and use third‑party and engagement documentation during assessment activities. The Document Management System (DMS) works with SAE to make documents available during assessments. When a document is uploaded or updated in DMS, the system retrieves the file and associated metadata so the information can be made
available during assessment activities.

This capability reduces manual effort by ensuring that essential vendor documentation remains accessible throughout the assessment process, while still allowing users to review, edit, and finalize their responses.

For more information, see [AI-assisted questionnaire pre-fill using the Document Management System](https://servicenow-prod.fluidtopics.net/FSDMgt7CjpoWSV2Qaz2BzQ "Use the Document Management System (DMS) with the Smart Assessment Engine (SAE) to automatically generate draft responses for third‑party risk assessment questionnaires using vendor documents and previously answered assessments.").

## Now Assist document skills {#tprm-dms__section_bd2_p3j_jhc}

If your organization uses DMS and ServiceNow Otto for TPRM, you can leverage AI-driven skills to streamline document-heavy workflows. These capabilities reduce manual effort, improve accuracy, and accelerate risk tasks. Now Assist for Document Management and ServiceNow Otto for TPRM offer the following key skills:

* TPRM issue summarization-- Condenses complex third-party risk issues into actionable summaries, helping risk analysts review and respond faster.

  For more information, see [TPRM issue summarization skill](https://servicenow-prod.fluidtopics.net/UtwGRXkG8BG6WMH0XL5etg "The issue summarization skill in ServiceNow Otto for Third-party Risk Management (TPRM) uses generative AI to create concise summaries of vendor-related issues, helping assessors quickly review risk details, improve consistency, and accelerate remediation.").
* Smart documents -- Summarizes risk management documents and provides quick Q\&A, reducing manual review and speeding up due diligence.For more information, see [Smart Documents](https://www.servicenow.com/docs/access?context=now-assist-skills-smart-documents&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).

* Extract information from documents -- Uses AI to pull specific data points (such as risk indicators, compliance clauses, or contract terms) from large documents, reducing manual review time and improving accuracy.For more
  information, see [Extract information from documents](https://www.servicenow.com/docs/access?context=now-assist-extract-information-from-documents&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).

{#tprm-dms__ul_jkh_p3j_jhc}

For more information on Now Assist for Document Management skills, see [Explore Now Assist in Document Management](https://www.servicenow.com/docs/access?context=explore-now-assist-in-document-management&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US).

## Limitations {#tprm-dms__limitations}

* External users can't preview documents due to restrictions; they must download documents from the portal to view them.
* The third-party field is optional when creating a document. However, if the document is associated with a third party, this field is required. For internal documents with no third-party association, the field can remain empty.
* Document creation and versioning currently require separate steps.
**Related tasks**   

* [Create a document record](https://servicenow-prod.fluidtopics.net/KFx3LLH5k7pvxAbxt48Rtw "Use the Document Management system to create document records in Third-party Risk Management.")
* [Create a document version](https://servicenow-prod.fluidtopics.net/U~QYqXtGXH9x2BjDAb9DCg "Use the document management system to version documents in Third-Party Risk Management (TPRM).")
* [Link documents to a TPRM record](https://servicenow-prod.fluidtopics.net/HAf2M6ScYEt8I3VktAWcjA "Use the Document Management system to link documents to assessments, engagements, issues, and tasks for traceability in Third-party Risk Management (TPRM).")
* [Define document sharing permissions](https://servicenow-prod.fluidtopics.net/_mJFJWANXCIrJG_JyXw2bA "Controls who can view, edit, or manage a document using the Document Management system in Third-party Risk Management (TPRM).")
* [Upload and manage documents in the third-party portal](https://servicenow-prod.fluidtopics.net/sU1CNRIGMzK4AncCt_sObQ "Use the third-party portal to upload and manage documents for assessments, engagements, issues, and tasks in Third-Party Risk Management (TPRM).")  
**Related topics**   

* [Document approval and publish process](https://www.servicenow.com/docs/access?context=document-review-approval&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US)
* [Exploring Document Management](https://www.servicenow.com/docs/access?context=explore-doc-management&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US)
* [Explore Now Assist in Document Management](https://www.servicenow.com/docs/access?context=explore-now-assist-in-document-management&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US)
* [Exploring Document Intelligence](https://www.servicenow.com/docs/access?context=exploring-docintel&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US)

